THREATOPS
THREAT OPSThreat News › [NVD] CVE-2021-4034 (HIGH 7.8) — A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the callin

[NVD] CVE-2021-4034 (HIGH 7.8) — A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the callin

lownvdPublished 2022-01-28

CVE-2021-4034 CVSS: 7.8 HIGH Published: 2022-01-28T20:15:12.193

A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2021-4034